CVE-2026-102511: Apache PLC4X, Apache PLC4X, Apache PLC4X, Apache PLC4X: ADS discovery accepts spoofed responses and derives the connection target from them

Published Sep 30, 2026
·
Updated

Improper Verification of Source of a Communication Channel in the ADS discovery of the Go implementation of Apache PLC4X (PLC4Go) allows an attacker able to send UDP datagrams to the discovering host to redirect subsequent connections to an arbitrary, attacker-chosen address. The discovery result's connection address was derived from the AmsNetId claimed in the response body rather than from the datagram's actual source address. One spoofed discovery response can therefore insert an inventory entry pointing at any host, including hosts outside the local network, and an application that connects to discovered devices will open its ADS session, including any configured route credentials, to that host.

Additionally, discovery listeners in both implementations can be disabled by a single malformed datagram: - In PLC4Go ADS discovery, a short version block causes a panic that ends the listener for the rest of the discovery call, so legitimate devices answering afterwards are not reported. - In PLC4J, the ADS and EtherNet/IP discoverers stop on an unhandled exception from a malformed response. - The PLC4J Modbus discoverer can be made to spin indefinitely, consuming a CPU core, by a scanned host that sends a partial response.

Exploitation requires the application to invoke the discovery API, which is opt-in, and for the connection redirect, to act on the discovered items.

This issue affects Apache PLC4X: PLC4Go from 0.11.0 before 1.0.0; PLC4J ADS and Modbus drivers from 0.10.0 before 1.0.0; PLC4J EtherNet/IP driver from 0.11.0 before 1.0.0. PLC4Go is consumed as the Go module github.com/apache/plc4x/plc4go; versions refer to the corresponding Apache PLC4X releases.

Users are recommended to upgrade to version 1.0.0, which fixes the issue. Version 1.0.0 derives the connection address from the datagram's source address and logs a warning when the claimed AmsNetId disagrees with it.

Affected Software

4 affected components
Apache PLC4Go>=0.11.0<1.0.0
Apache PLC4J ADS driver>=0.10.0<1.0.0
Apache PLC4J Modbus driver>=0.10.0<1.0.0
Apache PLC4J EtherNet/IP driver>=0.11.0<1.0.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Apache PLC4X (PLC4Go; PLC4J ADS, Modbus, and EtherNet/IP drivers) to a version that resolves this vulnerability.

    Fixed in 1.0.0

Event History

Sep 30, 2026
CVE Published
via MITRE·08:03 AM
Data Sourced
via MITRE·08:03 AM
DescriptionWeakness
Data Sourced
via NVD·09:17 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What network access does an attacker need?

The attacker must be able to send UDP datagrams to the host performing discovery. For the PLC4Go connection-redirection issue, a single spoofed discovery response can create an inventory entry targeting an attacker-chosen address.

2

When could configured ADS route credentials be exposed?

Credentials can be sent if an application automatically connects to discovered devices. In PLC4Go, the spoofed discovery result can cause that ADS session, including configured route credentials, to be opened to the attacker-chosen host.

3

What availability impacts are described for the discovery implementations?

A malformed UDP response can stop discovery listeners in PLC4Go and PLC4J: a short version block panics the PLC4Go listener, while unhandled exceptions stop the PLC4J ADS and EtherNet/IP discoverers. The PLC4J Modbus discoverer can also be forced to spin indefinitely and consume a CPU core.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203